This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Microsoft delivers seven updates in October patch release

by Shaun Nichols

09 Oct 2012

View Comments

  • Tweet this
New Microsoft logo

Microsoft has released an October security update which includes seven bulletin postings and an update to the way Windows handles security keys.

The company said that the Patch Tuesday release would in all patch 20 different security vulnerabilities, including two which have been rated by the company as 'critical' risks and top deployment priorities.

The lone 'critical' bulletin remedies two security issues in the way Word handles Rich Text Format (RTF) code in documents and email messages. If exploited, the flaws could be used by attackers for remote code execution attacks.

"Only one of the two issues addressed by this bulletin is rated Critical, but in that case, an attacker could run code in the context of the logged- on user if they were to open a specially crafted Rich Text Format (RTF) file or previews or open a specially crafted RTF email message," the company said in a post to its TechnNet security blog.

Other bulletins in the October update address flaws in Office, SharePoint, SQL Server, Lync and Windows. The remaining six bulletins are rated as 'important' and include flaws for remote code execution, denial of service and elevation of privileges.

Microsoft is also issuing the final step in its efforts to improve encryption practices. The company on Tuesday made good on a promise to disable RSA security keys which are less than 1024 bits in length.

Paul Henry, forensics and security analyst with Lumension, said that administrators should have long since equipped themselves for the change over, and those who have not would be well-served to do so immediately.

"This patch has been optional since August and we hope you’ve taken the time to test it and patch it," Henry said.

"It will no longer be optional after today’s patches. Don’t let this be an 'I told you so' moment."

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

15%

58%

11%

8%

8%

Popular Threads

Powered by Disqus
BlackBerry Q5

BlackBerry Q5 video demo

BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

Analyst/Developer Credit Risk Reporting

We are working on behalf of a leading global bank who...

Automation Test Delivery Manager (hands on) - Multi-tool

Test Manager - Automation - Test Manager - Selenium...

Senior Project Manager / Programme Manager - POS , EPOS

Senior Project Manager / Programme Manager - POS , EPOS...

SharePoint Architect, Design, 2010, Shropshire, £50,000

Roc Search is currently working with their client, a...

Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.

To send to more than one email address, simply separate each address with a comma.